Test storeBrowse here; your agent changes your order. Nothing is charged, nothing ships.All PAP Sandbox stores
NorthlightFlowers
For agents
Personal Agent Protocol draft 0.1

For agents

Bouquets and plants. Find a bouquet, check delivery dates, then change a booked delivery. Nothing is charged and nothing ships. Start from poppy.json; everything else is linked from there.

The showcase task. Ask your agent:“Change Friday’s bouquet to the peonies and add a card.”

Endpoints

Discovery
https://flowers.papsandbox.com/.well-known/poppy.json
Issuer
https://flowers.papsandbox.com
Issuer metadata
https://flowers.papsandbox.com/.well-known/oauth-authorization-server
Token
POST https://flowers.papsandbox.com/oauth/token
Sign-in
https://flowers.papsandbox.com/oauth/authorize
Direct Sign-In: authorization code with PKCE (S256), iss in the redirect.
Sign-out
POST https://flowers.papsandbox.com/oauth/revoke
API
https://flowers.papsandbox.com/poppy/openapi.json
OpenAPI 3.1. DPoP-bound Session Tokens on every call.
Extensions
operations v1 at https://flowers.papsandbox.com/poppy/operations

Tools

ToolNeedsWhat it does
search
GET /poppy/products
Signed out is fine Search the catalogue by name, category or tag. Prices in cents.
delivery_dates
GET /poppy/delivery-dates
Signed out is fine The delivery dates open for the next week or two.
my_orders
GET /poppy/orders
poppy:read The signed-in customer's open orders.
change_order
POST /poppy/orders/{order_id}/changes
poppy:write Propose a change to an order: move the delivery, add, swap or remove items. Returns HTTP 202 with an operation (operations extension v1); nothing changes until it is confirmed.

poppy.json

Open
{
    "protocol_version": "0.1",
    "organization": {
        "name": "Northlight Flowers",
        "domain": "flowers.papsandbox.com"
    },
    "auth": {
        "issuer": "https://flowers.papsandbox.com",
        "direct": {
            "scopes": [
                "poppy:read",
                "poppy:write"
            ]
        }
    },
    "apis": [
        {
            "type": "openapi",
            "url": "https://flowers.papsandbox.com/poppy/openapi.json",
            "description": "Product search, delivery dates, the customer's orders, and changes to a delivery"
        }
    ],
    "web": {},
    "extensions": {
        "operations": {
            "version": "1",
            "endpoint": "https://flowers.papsandbox.com/poppy/operations"
        }
    }
}

Issuer metadata

Open
{
    "issuer": "https://flowers.papsandbox.com",
    "token_endpoint": "https://flowers.papsandbox.com/oauth/token",
    "revocation_endpoint": "https://flowers.papsandbox.com/oauth/revoke",
    "authorization_endpoint": "https://flowers.papsandbox.com/oauth/authorize",
    "poppy_domains": [
        "flowers.papsandbox.com"
    ],
    "response_types_supported": [
        "code"
    ],
    "grant_types_supported": [
        "authorization_code",
        "refresh_token",
        "urn:ietf:params:oauth:grant-type:jwt-bearer"
    ],
    "code_challenge_methods_supported": [
        "S256"
    ],
    "token_endpoint_auth_methods_supported": [
        "private_key_jwt"
    ],
    "token_endpoint_auth_signing_alg_values_supported": [
        "ES256",
        "RS256",
        "EdDSA"
    ],
    "revocation_endpoint_auth_methods_supported": [
        "private_key_jwt"
    ],
    "dpop_signing_alg_values_supported": [
        "ES256",
        "RS256",
        "EdDSA"
    ],
    "authorization_response_iss_parameter_supported": true,
    "client_id_metadata_document_supported": true,
    "scopes_supported": [
        "poppy:read",
        "poppy:write"
    ]
}